Terminal and SSH

Terminal and SSH

Connect to a Kiste over SSH through kiste.run, without open ports, with pinned host keys and a shared connection.

kiste ssh                      # the current Kiste
kiste ssh review-42            # by name
kiste ssh review-42 -- uname -a   # run one command instead of a shell

kiste shell and kiste terminal are the same command. You log in as root.

How the connection works

kiste ssh runs your own OpenSSH client. Its connection travels over HTTPS to kiste.run and from there to the Kiste's SSH server, so:

  • no port is opened on your network or on the Kiste, and nothing listens on the public internet for SSH;
  • it works from wherever you can reach kiste.run, also behind strict firewalls and proxies that allow HTTPS;
  • the Kiste's host key is pinned: the CLI fetches it over your signed-in connection and SSH refuses anything else, so there is no "unknown host" prompt to click through;
  • only your account's device keys are accepted, password login is off.

The first ssh, scp or forward to a Kiste opens one shared connection that stays for two minutes after its last use. Every further one within that time skips the tunnel and the key exchange and starts instantly. (OpenSSH for Windows has no connection sharing, so there each connection is set up anew.)

Run a command

Anything after -- runs as a remote command, with standard input forwarded:

kiste ssh review-42 -- tar czf - /workspace/results > results.tgz
kiste ssh review-42 -- 'cat >> notes.txt' < local-notes.txt

kiste ssh then exits with the remote command's status. Leading options after -- go to ssh itself:

kiste ssh review-42 -- -L 8080:localhost:8080

For scripts, kiste exec is usually better: it runs a program without a shell, returns its exact output and status, and never needs a terminal. See Run commands.

kiste ssh review-42 --print-command

prints the exact, safely quoted OpenSSH command line without connecting, for tools that want to run ssh themselves.

Plain ssh, scp and editors

Signing in sets up NAME.kiste as an SSH host on your computer, so plain ssh review-42.kiste, scp, rsync and editors like VS Code work too. See SSH configuration and editors.

Limits

  • An SSH connection closes after one hour without any traffic in either direction. The CLI sends keep-alives every 15 seconds while a session is open, so an interactive shell stays.
  • An account can have 32 SSH connections open at once (L12).
  • Stopping, restarting or deleting the Kiste and signing out everywhere close its SSH connections.

Errors you may see

CodeMeaning
K03The Kiste isn't running. Start it with kiste start NAME.
K04The Kiste is still starting; its SSH server isn't listening yet.
N08The Kiste didn't accept this computer's key. Run kiste login on this computer.
L12Too many SSH connections are open.

On this page